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' Abstract. - In this paper, a new decoy-state scheme for quantum key distribution with 

£S| , parametric down-conversion source is proposed. We use both three-intensity decoy states and 

■ their triggered and nontriggered components to estimate the fraction of single-photon counts 
and quantum bit-error rate of single-photon, and then deduce a more accurate value of key 
generation rate. The final key rate over transmission distance is simulated, which shows that 
we can obtain a higher key rate than that of the existing methods, including our own earlier 

^ work. 
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Introduction. - Quantum key distribution has attracted extensive attentions for its un- 
conditional security compared with conversional cryptography [1-6] . However, there still exist 
^j*. several technical limitations in practice, such as imperfect single-photon sources, large loss 
channels and inefficient detectors, which will impair the security. Fortunately, many methods 
have been devised to deal with these imperfect conditions [7-12], among which, decoy-state 
method is thought to be a very useful candidate for substantially improving the performance 
of QKD. 

Decoy-state method was firstly proposed by Hwang [10], and advanced by Wang and Lo 
et al. [11-15] assuming a weak coherent source (WCS). Subsequently, it was extended to 
parametric down- conversion sources (PDCS) [16-18]. The main idea of decoy-state method 
is to randomly change the intensity of each pulse among different values, which allows one to 
estimate the behavior of vacuum, single-photon and multi-photon states individually. As a 
result, Eve's presence will be detected. Recently, more and more interesting ideas have been 
put forward to improve the performance of QKD [17, 19,20], such as the one by Adachi et 
al. [19]. In their proposal, both triggered and nontriggered components of PDCS are used to 
do some estimations for final secure key, and it needs only one intensity to transmit. However, 
because the intensity cannot be changed during the whole experiment, and dark counts cannot 
be measured directly, then the worst case of their contribution must be considered, which will 
inevitably limit final key rate and transmission distance. 
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In this paper, we propose a new practical decoy-state scheme with PDCS, in which not 
only three decoy states with different intensities (0, fi, ^'), but also all their triggered and 
nontriggered components are used to estimate the lower bound of fraction of single photon 
counts (Yi) and upper bound of quantum bit-error rate (QBER) of single-photon (ei). As a 
result, a more accurate value of key generation rate, compared with existing methods, can be 
obtained. 

Improved decoy state method. - In our new scheme, we can essentially use almost the 
same experimental setup as that in our previous proposal [18], except that Bob's detector 
need to work no matter what Alice's detector is triggered or not. 

As is well known, the state of two-mode field from PDCS is [21,22]: 



Pn = 



n=0 
X n 



(1 + x) 

where |n) represents an n-photon state, and x is the intensity (average photon number) of 
one mode. Mode T (trigger) is detected by Alice, and mode S (signal) is sent out to Bob. We 
request Alice to randomly change the intensity of her pump light among three values, so that 
the intensity of one mode is randomly changed among 0, u, u' (and u < u'). 

We denote q n as the probability of triggering at Alice's detector when an n-photon state 
is emitted, 

g„ = l-(l-»M) n , n = 1,2,3... (1) 
where r\A is the detecting efficiency at Alice's side, then the nontriggering probability is 
(1 — q n ) ■ We define Y n to be the yield of an n-photon state, i.e., the probability that Bob's 
detector clicks whenever Alice sends out state |n); we also define Q n be the gain of a n-photon 
state, i.e., the rate of events when Alice emits n-photon state and Bob detects the signal, 
which can be divided into two groups, triggered by Alice Q„\ and the rest qI"*^; and Q x be 
the overall rate according to intensity x, (x can be 0,u, //), it can also be divided into two 
groups, triggered by Alice Qx \ and the rest <3x"*\ which can be expressed as: 



^.y.^ty.^r-^, (3) 

where dA is the dark count rate of Alice's detector. 

In the next step, we will use the triggered events of « and the nontriggered events 

of u' (Q^) to deduce a tight bound of the fraction of single-photon counts (Yi). 
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The two equations lead to: 



i - (i - vaY 



1-(1-»M) 2 

VA 



(1 - »M) S 



1 /x' 



n=3 



i - (i -va) 2 i + h\ i + h'J 1 1 + n' \1 + /i 

1 - (1 - M v 2 



+ 



1- (1-jja) 2 (l + /i)"(l+/x') 2 



0--VA) 



i n 2 
n-2 A* A» 



(l+M'ra+M) 2 



(6) 



Assuming the condition 



/n o 
N n-2 A* A* 



1 - (1 - 7?a)" AtV /, _ xn-z 

1-(1- ??A )2 (1 + At )«(l+At') 2 J (1 + M ')"(1+m) 2 



< 



can be satisfied, i.e. 



A*< 



1 + fx' — ap,' ' 



(7) 



where a = ^ — n ^'_^ 1 _ r j'^r l VA ' 1 ^ ™ 2 , (because the values of yu and \i! can be chosen indepen- 
dently, the assumption above can be easily satisfied in experiment,) then Eq. (7) leads to the 
following inequality: 



Y 



Yi > Yf = 



^ a 



f A 1 ' *) 1 ^ f -i^V 



(8) 



This gives rise to the gain of single-photon pulse for triggered and nontriggered components 
as: 



Q { ' ] (x)=Y lVA - 



Q { rHx) = n(i-VA)j^, 



(9) 
(10) 



and x may be \l or // here. Also, if we have observed the quantum bit-error rate (QBER) for 
triggered and nontriggered pulses of intensity x, Ex \ Ei ut \ we can upper bound the QBER 
value of single-photon pulse as: 

(11) 
(12) 



n + x) 2 eY'Qx - (i + .x)y cW2 

ei < 77 = e OJ 

M + .T) 2 4 ut) 0i ut) - (1 + z)F (l - <k)/2 
e i S \ = e 6i 



Ki(l-J7 A )a: 
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Combing the two bounds, we have: 

e\ = min{e Q ,e b } . (13) 

Normally, we use the value from x — fi for a tight estimation of e\. Given all these, we can 
use the following formula to calculate the final key-rate of triggered signal pulses [9] : 

R {t) > \ {-Q$f h 2 (e$) + gw + w {1 _ H2 (ei)] } , (14) 

where the factor of i comes from the cost of basis mismatch in Bennett-Brassard 1984 (BB84) 
protocol; f{E ll i) is a factor for the cost of error correction given existing error correction 
systems in practice. We assume / = 1.22 here [23]. H 2 (x) is the binary Shannon information 
function, given by 

H 2 (x) = -x\og 2 (x) - (1 - x) log 2 (l - x). 

Furthermore, if the transmission distance is not so large, the nontriggered component can 
also be used to generate secret key just as in Adachi et al's proposal [19]: 

R{both) > i { _ Q w / H2 ^ _ Q <p )f ^ H2 ^ 

+ Q { o t} + Q { ut) + (Q? + Q[ t] ) [i - H 2 ( ei )]}. (15) 

In this case the final key rate is given by: R — max {R^\ R( both ) }. 

Numerical simulation. - In an experiment, we need to observe the values of Qq \ 
Q { *), Q { Ut \ Q^ t] , and E { J\ E ( *}, E { ^\ E { ^\ and then deduce the lower bound of 

fraction of single-photon counts (Yi) and upper bound QBER of single-photon pulses (ei) by 
theoretical results, and then one can distill the secure final key. In order to make a faithful 
estimation, we need a channel model to forecast what values for Q^ 1 , Q$ , Q^) , Qq 1 ^ , , 

and Ep \ £y\ E^f* would be, if we did the experiment without Eve in principle. 

Suppose r\ is the combined overall transmittance and detection efficiency between Alice 
and Bob; tAB is the transmittance between Alice and Bob, tAB = 1CP qL / 10 ; tjb is the trans- 
mittance in Bob's side, r\ = Iab-Vb- Following these assumptions, Y n = ds + 1 — (1 — »?)", 
which approximates 1 — (1 — rj) n when n > 1, and the observed value for Q$ and should 
be: 

Q ( t) = <UdB_ + g + i (i _ ^ ^ )B] (16) 

i=l U 



i=l l- 1 - + 

where x can be /i or //, and ds is the dark count rate of Bob's detectors. 
We use the following for the error rate of an n-photon state [12]: 



oc 

B , \ ~> 



e Q d B + e d [l - (1 - r,) n ] 
d B + l-(l-v) n ' 



(18) 



where e = 1/2, a is the probability that the survived photon hits a wrong detector, which 
is independent of the transmission distance. Below we shall assume to be a constant. 
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Fig. 1: Fig. 1 (Color online) Final key rates vs transmission distance for decoy-state method. 
The solid line is the ideal result where the fraction of single-photon counts and QBER of 
single-photon pulses are known exactly; the dotted lines and dashed lines are the simulation 
results with hnite decoy-state method, among which, the upper line is our new result using 
only triggered events with \l = n>1 , ; the lower line is the result of our previous proposal 

with ji = 0.1, (// has the optimal value at each point in each line.) 

Therefore, the observed values should be: 

oo 

4 t] - ==s . (19) 

oo 

/ (#) 

E^ = ^ ■ (20) 

In practical implementation of QKD, we often use non-degenerated down-conversion to 
produce photon pairs [24-26], with one photon at the wavelength convenient for detection 
acting as heralding signal, and the other at the telecommunication windows for optimal prop- 
agation along the hber or in open air acting as heralded signal. We can now calculate the hnal 
key rate with the assumed values above. For convenience of comparing with the results of 
Adachi et al. [19], we use the same parameters as used in their paper which mainly come from 
Gobby, Yuan and Shields (GYS) experiment [27]. At Alice's side, d,A = 10~ 6 ,?/a = 0.5; at 

Bob's side, d B = 1.7 X 10~ 6 , rj B = 0.045, e d = 0.033; and the channel loss is a = 0.21(dB/km). 

At each distance we choose the optimal value for //, so that we can have the highest key rate, 
and the final results are shown in Fig. 1, 2, 3 (according to Eq. (7), /i = 1+ r$z^jp is chosen 
in our new proposal). 

Fig. 1 shows the key generation rate against transmission distance compared with our 
previous results [18], (only triggered events are used.) It shows that our new scheme can 
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Fig. 2: Fig. 2 (Color online) Final key rates vs transmission distance for decoy-state method. 
The solid line is the ideal result where the fraction of single-photon counts and QBER of 
single-photon pulses are known exactly; the dotted lines and dashed lines are the simulation 
results with finite decoy-state method, among which, the upper line is our new result using 
both triggered and nontriggered events with /i = pp^-^rp ; the lower line is the result of our 
previous proposal with fi = 0.1, (// has the optimal value at each point in each line.) 



generate a higher key rate than the old one even using only triggered signal. 

Fig. 2 shows the key generation rate against transmission distance compared with our 
previous results [18], (both triggered and nontriggered events are used.) From it we can see 
that our new results can approach the ideal values very closely. Moreover, there is no need 
to use a quite weak decoy state or nontriggered signal. For example, at the distance of 50 
km, setting fj,' opt = 0.255, = 0.113,77,4 = 0.5 in our new scheme, and fj,' t = 0.143, /i = 
0.113, r]A = 0.5 in the old one, we can get a ratio of key rate between the two scheme as 3.8. 
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Fig. 3: Fig. 3 (Color online) (a) The optimal value of /j,' vs transmission distance. The upper 
line is the result of our new proposal ( /i = 1+ , ), and the lower line is the result of Adachi 
et al. (b) The ratio of key rates between our new proposal and Adachi et aPs vs transmission 
distance. 
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The reason that we can get a more accurate estimation of key rate (R) in the new proposal 
is as follows: we don't omit those high order items (in formula (6)) in the deduction of Y\, 
but use them to deduce a relationship between the intensity of decoy state (/x) and signal 
state (yu'), which inevitably results in a more bound estimation of Yi.(In addition, there is an 
inflexion in curve c (d) at the distance about 134 km, because the nontriggered events cease 
to contribute to the key rate.) 

Fig. 3 (a) shows the optimal values of // in our new proposal (setting /i = 1+ ^_ atl , ) 
and those in Adachi et aVs; Fig. 3 (b) shows the ratio of the key generation rate between 
our new scheme and Adachi et aVs against transmission distance, (both triggered events and 
nontriggered events are used.) It shows that our result is always larger than theirs when using 
almost the same level of data size [28]. 

From the figures above, we can see that, our new results are better than those of both our 
previous proposal and Adachi et al's. As is known [14], to give a more accurate estimation 
of the key rate, the value of ^ should be chosen to be the smaller the better. In our previous 
proposal, the key rate could also be very close to the ideal value given a very weak decoy 
state \i. However, in a practical experiment, considering statistical errors, [i cannot be too 
weak. So in our new scheme, we deduce a relation between [i and // , and at each point, 
both [i and \x' can be chosen with optimal values, which results in a more accurate estimation. 
Comparing with Adachi et a/'s proposal, the advantages of our proposal are as follows: Firstly, 
dark counts can be measured directly; secondly, a weaker decoy state \i is used to get a more 
accurate estimation of Y\ and ei, and a stronger signal of \i' is used to get a higher secure key 
rate. 

Conclusion. - In summary, we have proposed a new decoy-state scheme in QKD with 
PDCS, in which we use both three-intensity decoy-states and their triggered and nontriggered 
components to get a tight bound of the fraction of single-photon counts and single-photon 
QBER, This allows us to accurately deduce the value of key generation rate. Finally, the key 
generation rate vs transmission distance is numerically simulated. The simulations show that 
our new results are better than those of the existing proposal. Furthermore, our proposal only 
assumes existing experimental technology, which makes the scheme a practical candidate in 
the implementation of QKD. 
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